CVE Tools

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

The Hacker NewsBy The Hacker News

PatchcPanelWHM

Our summary

cPanel has released a security update to address CVE-2026-67401, a critical vulnerability affecting all supported versions of cPanel and WHM. This flaw, classified as an SQL injection within the EmailTrack functionality, permits an authenticated hosting account with specific mail privileges to create arbitrary files and escalate privileges to execute code as the root user. Because this level of access grants full administrative control over the server, it exposes all customer data and infrastructure to potential compromise. Administrators must immediately update their systems to the designated fixed builds, such as 11.110.0.143 or 11.134.0.55, by running the upgrade script or using the WHM interface.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store